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Among those who make a living from the science of secrecy, worry and paranoia are just signs of professionalism. Can we protect our 
secrets against those who wield superior technological powers? Can we trust those who provide us with tools for protection? Can we even 
trust ourselves, our own freedom of choice? Recent developments in quantum cryptography show that some of these questions can be 
addressed and discussed in precise and operational terms, suggesting that privacy is indeed possible under surprisingly weak assumptions. 

Subject terms: Quantum information Information technology 

Edgar Allan Poe, an American writer and an amateur cryptographer, once wrote "... it may be roundly asserted that human ingenuity cannot concoct a 
cipher which human ingenuity cannot resolve . . ." 1 . Is it true? Are we doomed to be deprived of our privacy, no matter how hard we try to retain it? If the 
history of secret communication is of any guidance here, the answer is a resounding 'yes'. There is hardly a shortage of examples illustrating how the 
most brilliant efforts of code-makers were matched by the ingenuity of code-breakers 2 . Even today, the best that modern cryptography can offer are 
security reductions, telling us, for example, that breaking RSA, one of the most widely used public key cryptographic systems, is at least as hard as 
factoring large integers 3 . But is factoring really hard? Not with quantum technology. Indeed, RSA, and many other public key cryptosystems, will 
become insecure once a quantum computer is built 4 . Admittedly, that day is probably decades away, but can anyone prove, or give any reliable 
assurance, that it is? Confidence in the slowness of technological progress is all that the security of our best ciphers now rests on. 

This said, the requirements for perfectly secure communication are well understood. When technical buzzwords are stripped away, all we need to 
construct a perfect cipher is shared private randomness, more precisely, a sequence of random bits known as a 'cryptographic key'. Any two parties 
who share the key, we call them Alice and Bob (not their real names, of course), can then use it to communicate secretly, using a simple encryption 
method known as the one-time pad 5 . The key is turned into a meaningful message by one party telling the other, in public, which bits of the key should 
be flipped. An eavesdropper, Eve, who has monitored the public communication and knows the general method of encryption but not the key will not be 
able to infer anything useful about the message. It is vital though that the key bits be truly random, never reused, and securely delivered to Alice and 
Bob, who may be miles apart. This is not easy, but it can be done, and one can only be amazed how well quantum physics lends itself to the task of key 
distribution. 

Quantum key distribution, proposed independently by Bennett and Brassard 6 and by Ekert 7 , derives its security either from the Heisenberg uncertainty 
principle (certain pairs of physical properties are complementary in the sense that knowing one property necessarily precludes knowledge about the 
other) or the monogamy of quantum entanglement (certain quantum correlations cannot be arbitrarily shared). At first, the idea of using quantum 
phenomena to improve secrecy was nothing more than an academic curiosity, but over time, with the progress of quantum technologies, it was 
embraced by experimental physicists and eventually turned into a viable commercial proposition. But even though quantum cryptography can offer the 
best security available at present, it is not immune to attacks exploiting botched implementations (see, for example, refs 8, 9, 1 0, 1 1 for practical 
illustrations). The flaws in the design may be unintentional, the result of ignorance or negligence on the part of some honest individuals who design 
quantum cryptosystems; but they can also be malicious, secretly implanted by powerful adversaries. Should we not then dissect our cryptographic 
devices, analyse them and make sure that they do exactly what they are supposed to do? Given that some of the flaws may be unknown to us, what 
exactly should we be looking for? It has long been believed that here we reach the li mits of privacy, and that at this point whoever is more 
technologically advanced, be it the NSA, GCHQ or some other agency, has the upper hand. Surprisingly, this is not the case. 

Recent research shows that privacy is possible under stunningly weak assumptions. All we need are monogamous correlations and a little bit of 'free 
will', here defined as the ability to make choices that are independent of everything pre-existing and are hence unpredictable 12, 13 . Given this, we can 
entertain seemingly implausible scenarios. For example, devices of unknown or dubious provenance, even those that are manufactured by our 
enemies, can be safely used to generate and distribute secure keys. There are caveats, of course: the devices must be placed in well-isolated 
locations to prevent any leaks of the registered data, and the data must be analysed by a trusted entity. Barring this, once the devices pass a certain 
statistical test they can be purchased without any knowledge of their internal working. This is a truly remarkable feat, also referred to as 'device- 
independent' cryptography 14 ' 15, 16, 17, 18, 19,20 Needless to say, proving security under such weak assumptions, with all the mathematical subtleties, 
is considerably more challenging than in the case of trusted devices, but the rapid progress in the past few years has been very encouraging, making 
device-independent cryptography one of the most active areas of quantum information science. 

In fact, some of the device-independent schemes do not even rely on the validity of quantum theory 21, 22, 23, 24 , and they therefore guarantee security 
against adversaries who may have access to superior, 'post-quantum', technologies. The adversaries may even be given control over the choices 
made by Alice and Bob during the key distribution protoco 25 . As long as this control is not complete, Alice and Bob can do something about it. It turns 
out that 'free will' or, more specifically, the ability to make unpredictable, and, therefore, random, choices can be amplified 26 . Randomness 
amplification has recently triggered a flurry of research activity, culminating in a striking result: anything that is not completely deterministic can be made 
completely random 27, 28 . This means, as we explain below, that as long as some of our choices are random and beyond control of the powers that be, 
we can keep our secrets secret. 



The power of free choice 

If there is one encryption method that comes close to a perfect cipher, it is the one-time pad. As we have already explained, its security critically relies 
on the randomness and secrecy of the cryptographic key. There is a snag, however, known as the 'key distribution problem'. Each key bit can be used 
only once, to encrypt one single message bit. To maintain their private communication, Alice and Bob must find a way to generate and distribute fresh 
key bits continuously. But how? 

Let us put all the practicalities aside, just for a moment, and dream about something that would solve the key distribution problem. For example, 
imagine that Alice and Bob were given two magically linked coins, which always come out the same side up — either two heads or two tails — with equal 
probabilities. Alice and Bob can then toss such coins at their respective locations, writing '0' for heads and '1 ' for tails. The resulting binary strings will 
be random and identical, but will they be secret? Not necessarily. Technologically superior Eve could have manufactured an additional coin, magically 
linked to the coins held by Alice and Bob. The three coins always tally and Eve knows all the bits in the string. 

Clearly, to achieve secrecy we must let Alice and Bob do something that is beyond Eve's control. For example, Alice and Bob may be given a choice 
between two different coins; Alice can toss either coin A^ or coin A 2 and Bob, either B 1 or B 2 . For each toss they must choose one of the two; 
tossing both /\ 1 and A 2 or both S 1 and B 2 is forbidden. Suppose, again, that the coins are magically linked; Alice and Bob's coins always come out 
the same, except when they toss A 1 and B 2 , which always come out opposite. The magic can be succinctly summarized by the following four 
conditions 29 ' 30 (Fig. 1): 

A,=JJj, B|=Aj, Ai=&i, flj^Aj (']] 

These conditions are clearly contradictory; it is impossible to assign values to A ^ , A 2 , B^ and S 2 so that all the four conditions are satisfied. But 
remember, Alice and Bob can toss only one coin each, and thus they can test only one of the four conditions in equation (1 ) at a time. Unperformed 
tosses do not have outcomes, and, hence, there is no contradiction here. 

Figure 1 : Magic correlations. 
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Alice and Bob choose and toss one coin each. Their choices are free, random and independent of each other, and the coins always come out the same way up, 
except when they toss /4 1 and S 2 , which always come out the opposite way up (represented by the red wiggly lines). Such correlations cannot be shared with a 
third party; for example, nobody can manufacture a coin that will always tally with any of the coins held by Alice or Bob. 

What if, say, Alice could break the rule and toss both of her coins, A 1 and A 2 , in one go? It turns out that she would deprive Bob of his free choice. 
Suppose that Alice tossed first (correlations are not affected by the chronological order of the tosses) and that her outcomes are such that A 1 = A 2 . 
Then Bob has no choice but to toss S 1: because this is the only choice compatible with the conditions in equation(1). Similarly, if A^ ?A 2 , the only 
choice left to Bob is to toss S 2 . This simple argument implies that the magic coins cannot be cloned. Having a clone, Z, of, say, A^ (such that Z= A{), 
and being able to toss it together with A 2 would lead to the same contradictions as tossing both A 1 and A 2 . The existence of Zdeprives Bob of his 
free choice. The conclusion is that if Alice and Bob have free choice then the magic correlations must be monogamous, that is, nothing else can be 
correlated to their coins. This turns the tables on Eve. Neither she nor anyone else can manufacture a coin that will always tally with any of the coins 
held by Alice or Bob. All ingredients for secure key distribution are now in place. 

Key distribution 

To establish a cryptographic key, Alice and Bob toss their magic coins. For each toss, Alice and Bob choose randomly, and independently of each 
other, which particular coin will be tossed: Alice is choosing between /A 1 and A 2 , and Bob, between B 1 and B 2 . After the toss, they announce publicly 
the coins they selected, but not the outcomes they registered. The outcomes are secret, because the coins cannot be cloned, and identical, because 
the coins are magically linked (except when A 1 and B 2 are tossed, in which case either Bob or Alice must flip his or her bit). The net result is that Alice 
and Bob share one secret bit. To establish a longer key, they simply repeat this procedure as many times as required. 

We note that Alice and Bob do not need to make any assumptions about the provenance of the coins; as long as the coins comply with the conditions 
in equation (1 ), they are as good as it gets and could have been manufactured by anyone, adversaries included. But this compliance has to be checked. 
Alice and Bob can do it, for example, by revealing the outcomes of some randomly chosen tosses and checking if they agree with equation (1 ). Such 
publicly disclosed tosses are then discarded and the key is composed from the remaining tosses, outcomes of which have never been revealed in 
public. If Alice and Bob notice a deviation from the magic correlations, they abort the key distribution and try again with another set of coins. 

Here we have tacitly assumed that Alice and Bob can communicate in public, but in such a way that nobody can alter their messages; for example, they 
might use a radio broadcast or an advert in a newspaper, or some other way that prevents impersonations. This communication is passively monitored 
by Eve and is the only information she gathers during the key distribution, because the coins are tossed in well-isolated locations that prevent any leaks 
of the registered outcomes. Given this, the secrecy of the key is based solely on the monogamy of the magic correlations and on one innocuous but 




essential assumption: both Alice and Bob can freely choose which coins to toss. 



It seems that we have already achieved our goal. There is only one little problem with our, otherwise impeccable, solution of the key distribution 
problem, which is that the magic correlations do not exist. That is, we do not know of any physical process that can generate them. But all is not lost, 
because there are physically admissible correlations that are 'magical' enough for oir purposes. Welcome to the quantum world! 

The quantum of solace 

Quantum theory is believed to govern all objects, large and small, but its consequences are most conspicuous in microscopic systems such as 
individual atoms or photons. Take, for example, polarized photons. Millions of identically polarized photons form the familiar polarized light, but at the 
quantum level polarization is an intrinsic property of each photon, corresponding to its spin. Although the polarization of a single photon can be 
measured along any direction, the outcome of the measurement has only two values, indicating whether the polarization is parallel or orthogonal to the 
measurement direction. For our purposes, we will label these outcomes 0 and 1 . 

A number of quantum optical techniques can be employed to generate pairs of polarization-entangled photons. Such photons respond to 
measurements, carried out on each of them separately, in a very coordinated manner. Suppose that Alice and Bob measure the polarizations of their 
respective photons along different directions, a and 8. It turns out that, although the values 0 and 1 are equally likely to appear, Alice and Bob's 
outcomes tally with the probability 

rt» ! (*- 0 (2) 

This is just about everything you need to know about quantum physics for now. 

Let us now replace the coin tosses by appropriately chosen polarization measurements: instead of tossing coin /A 1 , Alice simply measures her photon 
along a 1 = 0; and instead of tossing A 2 , she measures the photon along a 2 = 2p/8. Similarly, Bob replaces his coin tosses B 1 and B 2 by 
measurements along directions 6 1 = p/8 and 8 2 = 3p/8, respectively. The resulting joint probabilities of all possible outcomes, obtained using 
equation (2) and the specified polarization angles, are shown in Table 1. 

Table 1 : Approximating magic correlations 

From a more general perspective, for any value of e, which can be considered the probability of deviation from the magic correlations, the table 
describes 'non-signalling' correlations: Alice, by choosing between A 1 and A 2 , cannot communicate any information to Bob, and vice versa Bob 
choosing between B-\ and B 2 cannot send any information to Alice. Neither of them can see through the statistics of the outcomes what the other one 
is doing. Correlations with e= 1 /4 are called 'classical', because they admit pre-assigned values of /A 1 , A 2 , f?i and B 2 . This is no longer the case when 
e< 1/4, because any pre-assignment is bound to violate at least one of the four conditions in equation(1 ). Surprisingly, as we have just seen, there are 
physically admissible correlations for which ecan reach sin 2 (p/8) " 0.146, which is the lowest value that can be achieved with quantum correlations 31 . 
Even though perfect magic correlations, with e= 0, do not exist, there is still some magic left in quantum correlations, and it can be exploited. 

Less reality, more security 

The impossibility of assigning numerical values to certain physical quantities, for example the different polarizations of a photon, has been baffling 

Or) 

physicists for almost a century . After all, most of us grew up holding it self-evident that there is an objective reality in which physical objects have 
properties that can be quantified and whose values exist regardless of whether we measure them or not. Shocking as it may be, our world is not of this 
kind. Statistical inequalities, such as e= 1/4, derived on the assumption that the values of unmeasured physical quantities do exist and commonly 
referred to as Bell's inequalities 33 , have been violated in a number of painstaking experiments 33 ' 34 ' 35, 36 ' 37, 38, 39, 40, 41 ■ 42 ' 43 ' 44 We shall not 
dwell on the philosophical implications of this experimental fact (volumes have been written on the subject), but simply point out that it should be 
embraced by all those who worry about secrecy because what does not exist cannot be eavesdropped, and so it is much easier to keep secrets in a 
non-classical world. 

Indeed, given the correlations parameterized by q it can be shown that the probability of Eve guessing correctly any particular outcome cannot exceed 
(1 + 4e)/2 (Box 1 ). Eve may know something about the outcomes (which is not good) but Alice and Bob, after running a statistical test and estimating e, 
know how much she may know (which is good). If eis low enough, this allows them to distil an almost perfect key from the outcomes, using a technique 
known as 'privacy amplification'. 45, 46 The basic idea behind privacy amplification is quite simple. Imagine that you have two bits and that you know 
your adversary knows at most one of them, but that you do not know which one. Add the two bits together (modulo 2); the resulting bit will be secret. 
Needless to say, given more bits, there are more sophisticated ways of achieving secrecy, to mention only two-universal hash functions 47 or 
Trevisan's extractor 48 . 

Box 1 : Eavesdropping quantified 



Full box 



In summary, whenever Alice and Bob are given any devices that generate correlated outcomes, they can run the key distribution protocol supplemented 
by a statistical 'honesty test' to estimate e. If this value is small enough, say e= 0.1 5, the end result, after privacy amplification, is a perfect 
cryptographic key. We obtain trusted privacy from untrusted devices, but what constitutes a device? We need to sort out one more thing before we can 



celebrate the arrival of the ultimate cipher. Should Alice and Bob trust the ultimate measuring and controlling devices; that is, should they trust 
themselves? 

Should we trust ourselves? 

We can hardly get more paranoid than that. Can we make free choices or are we held to the ransom of a greater force? In other words, what if we are 
manipulated? 

We have already stressed the power of free choice. Decisions such as which coin to toss and which polarization to measure must be made freely 
(randomly) and independently. If referring to the experimenter's 'free will' sounds too esoteric, then think about the random number generators that in 
practical implementations make such choices. Where is their randomness coming from? What if these random number generators are of dubious 
provenance, possibly manufactured by the same person who offered the key distribution kit? It is evident that without randomness there is no privacy: if 
everything is pre-determined, and all possible choices we make (with the help of tweaked random number generators or otherwise) are predictable or 
pre-programmed by our adversaries, then there is nothing that we can build our privacy on. Or is there? 

There is if the manipulation is not complete and there is a little bit of freedom left. If someone we trust tells us that such and such a fraction of the 
choices made by our random number generators cannot be determined by the adversary, then privacy is still possible because local randomness can 
be amplified 26 . Randomness amplification can itself be done with device-independent protocols, and it works even if the fraction of initial randomness 
is arbitrarily small or the devices are noisy 27, 28 . 

It all looks bizarre and too good to be true. Perfect privacy, secure against powerful adversaries who provide us with cryptographic tools and who may 
even manipulate us? Is such a thing possible? Yes, it is, but 'the devil is in the detail' and we need to look into some practicalities. 

Practicalities 

Quantum key distribution, in which security is tested by the degree of violation of Bell's inequalities, was proposed some time ago 7 and was followed 
shortly by a proof-of-principle experiment at what used to be called the Defence Research Agency (now Qinetiq) in Malvern, UK 49 . However, the 
device-independent character of this protocol has not been recognized until recently 15 . Moreover, proving the security of such a scheme in the 
presence of noise has not been easy. It has taken over a decade to agree on a useful definition of secrecy, even for trusted devices, and to conclude a 
long sequence of steadily improved security results 50, 51 ' 52, 53 that eventually took into account all the quantum resources that Eve can muster 54 . 
Dealing with untrusted devices is even more tricky and keeps many of our colleagues busy 55 ' 56 ' 57 . 

Although all security proofs infer secrecy from the monogamy of the correlations, a major challenge is to make these arguments quantitative and robust 
to noise and imperfections, and applicable to keys of finite size 58, 59 . There are other issues as well. For example, here we have taken for granted that 
Alice and Bob can estimate the parameter efrom a sufficiently large sample of their registered data. In the quantum domain, a statement of that kind 
requires a quantum version of what is known in classical statistics as de Finetti's theorem 54, 60 . It guarantees that, for instance, pairs of photons can 
be treated as individual objects with individual properties and without any hidden correlations to other pairs. These, and many other results, addressed 
a number of subtleties and, finally, twenty years after its inception, the original entanglement-based key distribution protocol 7 has been shown to offer 
security even if the devices are not fully trusted and are exposed to noise 15 ' 16, 17, 1 8i 1 9i 20 . This is assuming that quantum theory is all that there is, 
and that Eve is bound by the laws of quantum physics. However, if Alice and Bob are paranoid enough to give Eve some 'post-quantum' powers 
(technologies more powerful than quantum technologies which may rely on as-yet undiscovered physical phenomena that are not described by quantum 
physics), they can still resort to less efficient protocols that do not rely on quantum theory 21 • 22, 23, 24 We should stress, however, that device- 
independent protocols and their security proofs have not yet reached the level of sophistication that is now common for the device-dependent 
scenario. In particular, more work is needed to improve the efficiency of the key distribution protocols or to identify conditions under which untrusted 
devices may be reused in multiple rounds of such protocols. 

Given that violation of Bell's inequality is an experimental fact, what is it that prevents us from running the experiments that violated Bell's inequality 
again, but this time under the label of the device-independent key distribution? Convincing as they are, these experiments still leave some loopholes. 
For example, it is in principle possible that the photons detected in the experiments did not represent a fair sample of all photons emitted by the source 
(the 'detection loophole ) or that the various parts and components of the experiment were causally connected (the 'locality loophole'). Some of these 
concerns were addressed in more recent experiments 43, 44 , but, a single experiment that closes all the loopholes at once, demonstrating the ultimate 
violation of Bell's inequality, is still lacking. 

This is not so disturbing for physicists, because nature would have to be very malicious if it were to cheat us selectively — on locality in some 
experiments and in exploring detection loopholes in some other. In contrast, there is nothing to prevent an eavesdropper being malicious. In this 
adversarial setting, a proper experimental demonstration of device-independent cryptography requires a proper violation of Bell's inequalities. This is 
particularly true for the detection loophole. Imagine, for example, that Eve pre-programmed the devices assuming in advance a sequence of settings 
that Alice and Bob may choose for their measurements. Whenever her guess is correct, the devices will respond with pre-programmed results, and 
when it is not, one of the devices will simulate failure to respond. If Alice and Bob naively discard all the instances in which at least one of the devices 
failed to deliver a result, then they can be easily fooled by Eve. Thus, we do need the loophole-free violation of Bell's inequalities. 

Closing the detection loop-hole is very challenging, because almost any optical component adds losses and imperfections to the key distribution 
set-up, but it is within the reach of today's technology, especially with the rapid progress in photodetection techniques. If distance is not an issue, then 
we can achieve near-perfect detection efficiency using entangled ions rather than photons 40 , and this has been used to generate the first device- 
independent certified randomness 81 ' 82 . Short of full device independence, we can also entertain intermediate scenarios, where some parts of the 
devices are trusted and some are not. Indeed, proposals that address issues such as untrusted detectors 63, 64 offer significant improvements over the 
existing quantum key distribution schemes 85, 88 and move secure communication in interesting new directions. 



Experimental device-independent cryptography is far from easy, but technological progress so far has encouraged optimism. The days we stop 



worrying about untrustworthy or incompetent providers of cryptographic services may be not that far away. 
Conclusion 

Over the past decade or so, quantum cryptography has come of age, but the field is still an amazingly fertile source of inspiration for fundamental 
research. The search for the ultimate physical limits of privacy is still very much a work in progress, but we know that privacy is possible under 
surprisingly weak assumptions. Monogamous correlations, of whatever origin, and an arbitrarily small amount of free will are sufficient to conceal 
whatever we like. Free will is our most valuable asset. Come to think about it, without free will, there is no point in concealing anything anyway. 
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Joint probabilities of binary outcomes given the choices of Aj and By (/,_/ = 1,2). The parameter £ takes the value 0 for the magic correlations 
(see equation (1)). The lowest physically admissible value, e = sin 2 (n/8)* 0,146. can be obtained by measuring polarizations of appropriately 
entangled photons at some specific angles, for example 0, tt78, 2nV8 and 3ttY8, corresponding to A^ t S 1( A 2 and B 2 , respectively 
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Box 1 : Eavesdropping quantified 

Suppose that Eve wants to manufacture a device that outputs binary values, Z designed to tally with, say, /A 1 . Regardless of her technological 
prowess, Eve has limited chances to succeed. For any two outcomes, A, and B f the probabilities that they are equal to Z that is, Pr(Z= Aj) and 
Pr(Z= Bj), cannot differ by more than Pr(/1, ? Bj. This implies a sequence of inequalities: 

ft il=A t J - Pr U = S» \ < Pr * } 

Adding these inequalities together and taking into account that Pr(Z?/4 1 ) = 1 - Pr(Z= A^ ) gives 

where the quantity l 2 = Pr(/A 1 ? B-|) + Pr(B 1 ?A 2 ) + Pr{A 2 ? B 2 ) + Pr(B 2 = /A^ is the sum of the probabilities that any of the conditions in equation 
(1 ) is violated. The derivation presented here works for any A, and Bj, and, it is worth stressing, does not involve quantum theory. 

Although the values A^ , A 2 , S-| and B 2 do not coexist, all the probabilities used here involve only pairs of values, A, and B f which can be 
measured simultaneously. They can be determined from the statistics of the experimental data. For the polarization measurements described in 
the text, we would obtain l 2 = 4e where e= sin 2 (p/8)" 0.146. The bound thus asserts that Pr(Z = A{] = 0.793; that is, Eve's value, Z will deviate 
from Ai in more than 20% of the cases. 

The notion of magic correlations can be extended to cases where Alice and Bob choose between n =2 different measurements 67, 68 , with the 
conditions in equation (1) replaced by 

Ai-fiii-fc-4& .... An-fit* &*Ai (3) 

To approximate such correlations, Alice and Bob may use entangled photons and measure polarizations A, and specified by angles a, and Gj. 
These angles are chosen to be even and odd multiples of p/4n, respectively, so that the adjacent values of a, and Bj are p/4n radians apart. Then, 
according to equation (2), each of the conditions in equation(3) is satisfied, except with an error probability of e n = sin 2 (p/4n) < 1/n 2 . It can then be 
shown, by the same arguments as for the n = 2 case, that any attempt by Eve to compute a prediction, Z for the outcome of, say, /A 1 , can 
succeed with probability at most (1 + l n )/2, where /„ = Pr(Af ? B^) + Pr(B-| ?A 2 ) + ... + Pr(/4 n ?B„) + Pr(B n = A^ ). For any classical correlations, l n 
= 1 . In contrast, quantum theory admits correlations such that /„ = 2ne n < 2/a Consequently, in the limit of large n, the probability of Eve guessing 
the value of A^ correctly becomes 1/2; that is, A^ is uniformly random and independent of any information held by Eve. This observation is not 
only relevant for key distribution 21 , but has been crucial for randomness amplification 26 . 
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